HPE FlexNetwork MSR Series Configuration Manual page 596

Comware 7 security
Table of Contents

Advertisement

Step
1077.
Enter attack defense
policy view.
1078.
Enable global SYN
flood attack detection.
1079.
Set the global trigger
threshold for SYN flood
attack prevention.
1080.
Specify global actions
against SYN flood attacks.
1081.
Configure
address-specific SYN flood
attack detection.
Configuring an ACK flood attack defense policy
Step
1082.
Enter system view.
1083.
Enter attack defense
policy view.
1084.
Enable global ACK
flood attack detection.
1085.
Set the global trigger
threshold for ACK flood
attack prevention.
1086.
Specify global actions
against ACK flood attacks.
1087.
Configure
address-specific ACK flood
attack detection.
Configuring a SYN-ACK flood attack defense policy
Step
1088.
Enter system view.
1089.
Enter attack defense
policy view.
1090.
Enable
SYN-ACK
detection.
1091.
Set the global trigger
threshold
flood attack prevention.
Command
attack-defense
policy-name
syn-flood detect non-specific
syn-flood
threshold-value
syn-flood action { client-verify |
drop | logging } *
syn-flood
ipv4-address
IP
ipv6-address } [ vpn-instance
vpn-instance-name ] [ threshold
threshold-value
{ { client-verify | drop | logging }
* | none } ]
Command
system-view
attack-defense
policy-name
ack-flood detect non-specific
ack-flood
threshold-value
ack-flood action { client-verify |
drop | logging } *
ack-flood
ipv4-address
IP
ipv6-address } [ vpn-instance
vpn-instance-name ] [ threshold
threshold-value
{ { client-verify | drop | logging }
* | none } ]
Command
system-view
attack-defense
policy-name
global
syn-ack-flood
flood
attack
non-specific
syn-ack-flood
for
SYN-ACK
threshold-value
policy
threshold
detect
ip
{
|
ipv6
]
[
action
policy
threshold
detect
{
ip
|
ipv6
]
[
action
policy
detect
threshold
580
Remarks
N/A
By default, global SYN flood attack
detection is disabled.
The default setting is 1000.
By default, no global action is
specified for SYN flood attacks.
By default, IP address-specific SYN
flood
attack
detection
configured.
Remarks
N/A
N/A
By default, global ACK flood attack
detection is disabled.
The default setting is 1000.
By default, no global action is
specified for ACK flood attacks.
By default, IP address-specific ACK
flood
attack
detection
configured.
Remarks
N/A
N/A
By default, global SYN-ACK flood
attack detection is disabled.
The default setting is 1000.
is
not
is
not

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents